Favicon of ai-jail

ai-jail

A local sandbox for AI coding agents that restricts file, credential and network access on Linux and macOS. Open source under GPL-3.0.

ai-jail puts AI coding agents such as Claude Code inside a local operating system sandbox. It's for developers who want an agent to work on a project while limiting its access to the rest of their machine. Written in Rust and licensed under GPL-3.0, it runs on Linux and macOS; Windows users need WSL2 with the Linux backend.

The agent can edit the project directory by default, but it gets a separate temporary home. Host credentials and the full shell environment stay outside unless explicitly shared. Network access is off by default, as are GPU, display, Docker and SSH access. Files containing project secrets remain readable unless masked or blocked. A read-only lockdown mode supports work that shouldn't modify files.

Network permissions can be limited to named hosts instead of allowing unrestricted access. For compatible HTTP clients, a proxy can keep real API keys outside the sandbox and insert them only into requests to their assigned host. This substitution doesn't work inside opaque HTTPS CONNECT tunnels, and the supervising proxy sees the plaintext requests it handles. Optional local audit logs record launches and filtered network decisions, with a separate integrity check.

Linux uses bubblewrap with namespace isolation, plus Landlock, seccomp and resource limits where available. macOS relies on Apple's deprecated sandbox-exec interface. By default, repository-level policy can tighten restrictions but can't grant broader host access. Neither backend covers kernel or driver vulnerabilities, terminal emulator vulnerabilities, or every IPC and side-channel risk; hostile code still calls for a disposable VM.

Similar to ai-jail